Frontier labs block red teams from testing defenses, spawning an unfiltered-model business
It transfers the judgment of whether to refuse execution from the model maker to the customer, which explains why even Fortune 500 CISOs will seek out a model vendor that openly markets deregulation for red-team testing.
The video won't play here. Listen to the audio instead:
The argument · tap a timestamp to hear it
Frontier labs actively reject legitimate customers
Devin Thomas started Obliteration.ai after finding a cohort of security engineers, biotech researchers, synthetic-data teams, and defense contractors—whose daily work requires unlimited access to test attack methods or generate sensitive information—systematically blocked by frontier-model safety policies. These aren't malicious actors; they're professionals with legitimate needs. Obliteration positioned itself to serve this neglected segment and gained rapid media attention.
— Devin ThomasThe defender cannot obtain the same model as the attacker
Jason gives a concrete scenario: if OpenAI were testing attacks against Hugging Face, it would use its latest, most powerful model. But Hugging Face defending itself cannot access that same OpenAI version. Devin confirms this asymmetry exists—and not only from startups. Even large companies with special national-security project clearances struggle when models refuse to execute test instructions. Those shut out are not undercapable people; they are regulars.
— Devin Thomas / Jason CalacanisCustomers should define guardrails, not model vendors
Obliteration's product design does not crudely strip safety limits. It uses a two-layer architecture: a base open-source model with native refusal behavior removed, and a separate small model running guardrail policy that the customer configures. Devin calls this "inversion of control"—previously the vendor set boundaries for every customer; now customers set rules by their industry's compliance requirements, making some domains stricter than the original, others more permissive.
— Devin ThomasThe toolmaker is not liable for how users wield the tool
On who bears responsibility for misuse, Devin uses a hammer analogy to deflect legal risk: the company requires real identity registration through Stripe, creating a traceable path; law currently holds tool users responsible, just as the hammer maker and hardware store are not liable if someone uses a hammer to hurt someone. Obliteration provides no execution layer—only data in and data out. What users do with that data is their choice. He likens his company to the paper bag holding the hammer.
— Devin ThomasThe frontier advantage window has compressed to three months
Anthropic itself blogged that deregulated GLM has approached frontier-level cybersecurity capability, which Devin sees as source of industry anxiety. The word "frontier" implies permanent leadership—a hierarchy that never closes. But the moat is narrowing faster than expected: previously about one year behind, now roughly three months. As model capabilities converge, the "we are frontier" valuation story becomes harder to sustain.
— Devin ThomasResource abundance drives labs to take dangerous risks
Asked why AI company crawlers and red teams often overstep, Devin offers a rarely-heard explanation: as lab size grows and teams expand, researchers need projects to prove their value, so testing intensity scales up and reward functions get more aggressive. Jason calls this the first time he has heard this, but says it is "probably quite accurate"—resource surplus itself breeds risk. It is not necessarily a deliberate harmful choice; proving yourself useful naturally compounds into hazard.
— Devin Thomas / Jason CalacanisHourly billing persists, but its economic logic is shifting
To the debate on whether AI kills time-based fees, Jason counters with history: PCs, cloud computing, the internet—each previous disruptive technology kept hourly payment alive. People always have time and tools. What shifts is the pricing foundation. Simple legal documents no longer need hourly lawyer time, but expert-level AI tools let those experts ship better work in less time. He extends the analogy with luxury fashion designers and bridal gowns: customers pay not for speed, but for claiming the process and the person's experience and credibility.
— Jason CalacanisFounders should eliminate risks, not expand their team
When asked whether AI shifts investor preference away from multi-founder teams, Jason says efficiency is not the bottleneck—solo founders at high intensity have always existed. The real constraint early on is context-switching cost; one person struggles to simultaneously solve product-market fit, hiring, and fundraising. His framework: throw three-founder, two-founder, and solo-founder teams in the same bucket and draw at random; investors bet three-to-one-to-one unless the solo founder proves they have neutralized a specific risk—sustained product-market fit growth, or steadily rising sales. Once risk is eliminated, valuation and funding appetite follow.
— Jason CalacanisIn their own words · checked verbatim
And even if they have access to those special cyber programs, still, many of them, our customers are still complaining about refusals. And these are big corporations.
Devin Thomas3:06
Like if someone goes and takes a hammer and hits someone with it, right? Like the creator of the hammer is not necessarily liable in that case, right?
Devin Thomas7:21
Maybe before it was a year, they were a year behind. I would say today they're maybe around three months behind.
Devin Thomas9:25
I think it's kind of like if it bleeds, it leads type situation, where it's like it just people love these stories of these hacks.
Devin Thomas13:33
That's actually an insight I've never heard anybody make, Devin, that is actually perhaps super accurate, which is when you have an unlimited amount of resources and people looking to make an impact inside a company, they will try to have an impact.
Jason Calagans17:43
So the question is, is this tool so transformative that adding a person's time becomes irrelevant?
Jason Calagans32:02
So what risk can you eliminate? With three co-founders, you're eliminating one co-founder quitting risk, right?
Jason Calagans50:42
Figures
| Frontier vs. deregulated open-source cybersecurity capability gap | from approximately 1 year to approximately 3 months | 9:25 |
Glossary
- Obliteration / deregulation
- Pinpoint and modify neurons in a model that handle refusal behavior, removing safety guardrails.
- Inversion of control
- Transfer guardrail-definition authority from the model maker to the customers using the model.
- DeepSeek
- Chinese open-source large language model company; mistranscribed as "DeepSea" in the original.
How to listen
Cybersecurity red-teamers, enterprise CISOs, founders and investors interested in open-source model commercialization and AI startup pricing strategy.
Mid-episode sponsor segments for Odoo and Northwest Registered Agent can be skipped.